<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>Cybersecurity Canada</title>
    <subtitle>Free cybersecurity resources and assessment for Canadian small and medium businesses. Based on the Canadian Centre for Cyber Security&#39;s Baseline Cyber Security Controls.</subtitle>
    <link href="https://cybersecuritycanada.ca/feed.xml" rel="self" type="application/atom+xml"/>
    <link href="https://cybersecuritycanada.ca/" rel="alternate" type="text/html"/>
    <id>https://cybersecuritycanada.ca/</id>
    <updated>2026-06-25T00:00:00.000Z</updated>
    <author>
        <name>Cybersecurity Canada</name>
    </author>
    <entry>
        <title>Frontier AI and Cyber Security: What Canada&#39;s Cyber Centre Wants Businesses to Do Now</title>
        <link href="https://cybersecuritycanada.ca/news/posts/frontier-ai-cyber-security-cyber-centre-statement/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/frontier-ai-cyber-security-cyber-centre-statement/</id>
        <published>2026-06-25T00:00:00.000Z</published>
        <updated>2026-06-25T00:00:00.000Z</updated>
        <summary>On June 24, 2026, the Canadian Centre for Cyber Security warned that frontier AI is shrinking the time defenders have to respond — from days or weeks to hours. Here&#39;s what the statement means for Canadian businesses.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>Amazon Prime Day Scams: How Canadians Can Shop Safely During the June 23–26 Sale</title>
        <link href="https://cybersecuritycanada.ca/news/posts/amazon-prime-day-scams-how-canadians-can-shop-safely/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/amazon-prime-day-scams-how-canadians-can-shop-safely/</id>
        <published>2026-06-20T00:00:00.000Z</published>
        <updated>2026-06-20T00:00:00.000Z</updated>
        <summary>Amazon Prime Day runs June 23–26, 2026, and fraudsters are already registering thousands of fake Amazon sites. Here&#39;s how Canadians and their employees can spot Prime Day scams before they hand over a password or a card number.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>Anthropic&#39;s Call for a Global AI Pause: What It Means for Canadian Businesses</title>
        <link href="https://cybersecuritycanada.ca/news/posts/anthropic-global-ai-pause-what-it-means-for-canadian-businesses/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/anthropic-global-ai-pause-what-it-means-for-canadian-businesses/</id>
        <published>2026-06-06T00:00:00.000Z</published>
        <updated>2026-06-06T00:00:00.000Z</updated>
        <summary>On June 4, 2026, Anthropic — valued near $1 trillion — urged a coordinated global pause on frontier AI development, warning models may soon improve themselves without humans. Here&#39;s what it means for Canadian businesses.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>The Cybersecurity Canada Report 2026: Seven Findings Canadian SMBs Should Know</title>
        <link href="https://cybersecuritycanada.ca/news/posts/cybersecurity-canada-report-2026-key-findings/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/cybersecurity-canada-report-2026-key-findings/</id>
        <published>2026-05-24T00:00:00.000Z</published>
        <updated>2026-05-24T00:00:00.000Z</updated>
        <summary>Canadians lost a record CA$704M to fraud in 2025. Microsoft documented a threat actor specifically targeting Canadians. Mandiant says attackers now hand off compromised access in 22 seconds. Seven findings from the inaugural Cybersecurity Canada Report.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>Claude Mythos and Project Glasswing: What 10,000 AI-Discovered Zero-Days Mean for Canadian Businesses</title>
        <link href="https://cybersecuritycanada.ca/news/posts/claude-mythos-and-project-glasswing-what-canadian-businesses-need-to-know/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/claude-mythos-and-project-glasswing-what-canadian-businesses-need-to-know/</id>
        <published>2026-05-23T00:00:00.000Z</published>
        <updated>2026-05-23T00:00:00.000Z</updated>
        <summary>Anthropic&#39;s Claude Mythos Preview model has autonomously discovered more than 10,000 high- and critical-severity zero-day vulnerabilities under Project Glasswing. Here is what Canadian businesses should do while the patches catch up.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>CRA, Interac, and Canada Post: The Canadian Brand Phishing Playbook for SMBs</title>
        <link href="https://cybersecuritycanada.ca/news/posts/cra-interac-canada-post-canadian-brand-phishing-playbook-for-smbs/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/cra-interac-canada-post-canadian-brand-phishing-playbook-for-smbs/</id>
        <published>2026-05-14T00:00:00.000Z</published>
        <updated>2026-05-14T00:00:00.000Z</updated>
        <summary>Canadian SMB employees see CRA refund texts, fake Interac e-Transfer notifications, and Canada Post &#39;missed delivery&#39; SMS every week. Here&#39;s how to train your team to spot the Canadian brand phishing patterns generic training misses.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>Canvas Data Breach 2026: What the Instructure Hack Means for Canadian Universities and Businesses</title>
        <link href="https://cybersecuritycanada.ca/news/posts/canvas-data-breach-what-canadian-universities-and-businesses-need-to-know/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/canvas-data-breach-what-canadian-universities-and-businesses-need-to-know/</id>
        <published>2026-05-08T00:00:00.000Z</published>
        <updated>2026-05-08T00:00:00.000Z</updated>
        <summary>The Canvas data breach has hit UBC, SFU, the University of Toronto, OCAD, Western&#39;s Ivey, Mohawk College and Ontario Tech, with ShinyHunters claiming 275 million records across 9,000 schools. Here&#39;s what happened and what to do.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Threats"/>
    </entry>
    <entry>
        <title>Agentic AI Security for Canadian Businesses: What the New Cyber Centre Guidance Means</title>
        <link href="https://cybersecuritycanada.ca/news/posts/agentic-ai-security-for-canadian-businesses-cyber-centre-guidance/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/agentic-ai-security-for-canadian-businesses-cyber-centre-guidance/</id>
        <published>2026-05-03T00:00:00.000Z</published>
        <updated>2026-05-03T00:00:00.000Z</updated>
        <summary>Canada&#39;s Cyber Centre and four allied agencies published Careful Adoption of Agentic AI Services on May 1, 2026. Here&#39;s what the new agentic AI security guidance means for Canadian businesses considering AI agents.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>Canada Life Data Breach: What Canadians and Canadian Businesses Need to Know</title>
        <link href="https://cybersecuritycanada.ca/news/posts/canada-life-data-breach-what-canadians-need-to-know/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/canada-life-data-breach-what-canadians-need-to-know/</id>
        <published>2026-04-26T00:00:00.000Z</published>
        <updated>2026-04-26T00:00:00.000Z</updated>
        <summary>The Canada Life data breach exposed personal information for up to 70,000 people after attackers used one employee&#39;s account to reach a Salesforce environment. Here&#39;s what happened and what to do.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Threats"/>
    </entry>
    <entry>
        <title>Cybersecurity Laws in Canada: The 2026 Guide for Businesses</title>
        <link href="https://cybersecuritycanada.ca/news/posts/cybersecurity-laws-in-canada-2026-guide-for-businesses/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/cybersecurity-laws-in-canada-2026-guide-for-businesses/</id>
        <published>2026-04-19T00:00:00.000Z</published>
        <updated>2026-04-19T00:00:00.000Z</updated>
        <summary>A plain-language overview of every cybersecurity and privacy law that applies to Canadian businesses in 2026 — federal, provincial, and sector-specific — and how they connect to the Baseline Controls.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Compliance"/>
    </entry>
    <entry>
        <title>Cybersecurity Certifications in Canada: CyberSecure Canada and the Professional Credentials That Matter</title>
        <link href="https://cybersecuritycanada.ca/news/posts/cybersecurity-certifications-in-canada-cybersecure-canada-and-professional-credentials/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/cybersecurity-certifications-in-canada-cybersecure-canada-and-professional-credentials/</id>
        <published>2026-04-11T00:00:00.000Z</published>
        <updated>2026-04-11T00:00:00.000Z</updated>
        <summary>An overview of the cybersecurity certifications that matter in Canada in 2026 — the CyberSecure Canada program for organizations, and the professional credentials (CISSP, CISM, CISA, GIAC, CompTIA) businesses should look for when hiring or vetting providers.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Guide"/>
    </entry>
    <entry>
        <title>A Brief History of Cybersecurity in Canada: From Cold War Signals Intelligence to the Canadian Centre for Cyber Security</title>
        <link href="https://cybersecuritycanada.ca/news/posts/history-of-cybersecurity-in-canada/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/history-of-cybersecurity-in-canada/</id>
        <published>2026-04-04T00:00:00.000Z</published>
        <updated>2026-04-04T00:00:00.000Z</updated>
        <summary>Canada&#39;s cybersecurity institutions have a long, specific history — from the Second World War signals intelligence agency that became CSE, through PIPEDA and the Heartbleed era, to the Canadian Centre for Cyber Security and Bill C-26. A timeline for businesses and citizens.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>Understanding CVSS Scores: What the Numbers Behind Software Vulnerabilities Actually Mean</title>
        <link href="https://cybersecuritycanada.ca/news/posts/understanding-cvss-scores-what-the-numbers-behind-software-vulnerabilities-mean/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/understanding-cvss-scores-what-the-numbers-behind-software-vulnerabilities-mean/</id>
        <published>2026-03-30T00:00:00.000Z</published>
        <updated>2026-03-30T00:00:00.000Z</updated>
        <summary>When a vulnerability is rated 8.8 or 10.0, what does that actually mean for your business? Here&#39;s a plain-language guide to CVSS scores and why they matter.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>How to Choose a Cybersecurity Provider for Your Canadian Small Business</title>
        <link href="https://cybersecuritycanada.ca/news/posts/how-to-choose-a-cybersecurity-provider-for-your-canadian-small-business/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/how-to-choose-a-cybersecurity-provider-for-your-canadian-small-business/</id>
        <published>2026-03-24T00:00:00.000Z</published>
        <updated>2026-03-24T00:00:00.000Z</updated>
        <summary>Managed service providers, MSSPs, consultants, and vCISOs — the options for outsourced cybersecurity are growing. Here&#39;s how Canadian small businesses can evaluate providers, ask the right questions, and avoid common mistakes.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Guide"/>
    </entry>
    <entry>
        <title>Why Our Free Cybersecurity Assessment Doesn&#39;t Collect Your Data</title>
        <link href="https://cybersecuritycanada.ca/news/posts/why-our-free-cybersecurity-assessment-doesnt-collect-your-data/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/why-our-free-cybersecurity-assessment-doesnt-collect-your-data/</id>
        <published>2026-03-22T00:00:00.000Z</published>
        <updated>2026-03-22T00:00:00.000Z</updated>
        <summary>Most online assessment tools require your email before showing results. Ours doesn&#39;t collect anything — not your name, not your email, not your answers. Here&#39;s exactly how it works and why we built it this way.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>What Canadian Businesses Need to Know About Bill C-26</title>
        <link href="https://cybersecuritycanada.ca/news/posts/what-canadian-businesses-need-to-know-about-bill-c-26/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/what-canadian-businesses-need-to-know-about-bill-c-26/</id>
        <published>2026-03-20T00:00:00.000Z</published>
        <updated>2026-03-20T00:00:00.000Z</updated>
        <summary>Bill C-26&#39;s cybersecurity provisions — now reintroduced as Bill C-8 — would impose mandatory obligations on critical infrastructure operators in Canada. Here&#39;s what the legislation covers, who it affects, and why all Canadian businesses should be paying attention.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Compliance"/>
    </entry>
    <entry>
        <title>New PIPEDA Enforcement Actions: What Changed and What Canadian SMBs Must Do Now</title>
        <link href="https://cybersecuritycanada.ca/news/posts/new-pipeda-enforcement-what-changed-and-what-smbs-must-do/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/new-pipeda-enforcement-what-changed-and-what-smbs-must-do/</id>
        <published>2026-03-14T00:00:00.000Z</published>
        <updated>2026-03-14T00:00:00.000Z</updated>
        <summary>The Office of the Privacy Commissioner of Canada is enforcing PIPEDA more aggressively than ever. Here&#39;s what recent enforcement actions mean for small and medium businesses — and the practical steps to reduce your risk.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Compliance"/>
    </entry>
    <entry>
        <title>AI-Powered Phishing: What&#39;s Changed for Canadian Businesses in 2026</title>
        <link href="https://cybersecuritycanada.ca/news/posts/ai-powered-phishing-whats-changed-for-canadian-businesses/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/ai-powered-phishing-whats-changed-for-canadian-businesses/</id>
        <published>2026-03-08T00:00:00.000Z</published>
        <updated>2026-03-08T00:00:00.000Z</updated>
        <summary>AI tools have made phishing emails faster to create, harder to detect, and more convincing than ever. Here&#39;s what Canadian small businesses need to know — and what actually helps.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Threats"/>
    </entry>
    <entry>
        <title>Building an Incident Response Plan for Your Canadian Business</title>
        <link href="https://cybersecuritycanada.ca/news/posts/building-an-incident-response-plan-for-your-canadian-business/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/building-an-incident-response-plan-for-your-canadian-business/</id>
        <published>2026-03-07T00:00:00.000Z</published>
        <updated>2026-03-07T00:00:00.000Z</updated>
        <summary>The Canadian Centre for Cyber Security designates incident response planning as the first of its 13 Baseline Controls. Here is what the guidance says, what a plan includes, and what Canadian SMBs face without one.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>What to Do in the First 24 Hours After a Cyber Attack</title>
        <link href="https://cybersecuritycanada.ca/news/posts/what-to-do-in-the-first-24-hours-after-a-cyber-attack/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/what-to-do-in-the-first-24-hours-after-a-cyber-attack/</id>
        <published>2026-02-28T00:00:00.000Z</published>
        <updated>2026-02-28T00:00:00.000Z</updated>
        <summary>When a cyber attack hits, the decisions you make in the first hours determine how much damage your business sustains. This step-by-step guide walks Canadian small business owners through the critical first 24 hours.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Guide"/>
    </entry>
    <entry>
        <title>Cyber Insurance: What Canadian SMBs Need to Understand</title>
        <link href="https://cybersecuritycanada.ca/news/posts/cyber-insurance-what-canadian-smbs-need-to-understand/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/cyber-insurance-what-canadian-smbs-need-to-understand/</id>
        <published>2026-02-22T00:00:00.000Z</published>
        <updated>2026-02-22T00:00:00.000Z</updated>
        <summary>Cyber insurance adoption among Canadian businesses remains low, and denied claims are making headlines. Here is what the market looks like, what insurers are requiring, and what happens when those requirements are not met.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>Ransomware: What Canadian Businesses Need to Know Before, During, and After an Attack</title>
        <link href="https://cybersecuritycanada.ca/news/posts/ransomware-what-canadian-businesses-need-to-know-before-during-and-after-an-attack/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/ransomware-what-canadian-businesses-need-to-know-before-during-and-after-an-attack/</id>
        <published>2026-02-21T00:00:00.000Z</published>
        <updated>2026-02-21T00:00:00.000Z</updated>
        <summary>Ransomware remains the top cybercrime threat facing Canadian organizations. Here is what Canadian SMBs should do before an attack happens, what to do if one is underway, and how to recover.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Threats"/>
    </entry>
    <entry>
        <title>USB Drives and Portable Media: The Security Risk Sitting in Your Desk Drawer</title>
        <link href="https://cybersecuritycanada.ca/news/posts/usb-drives-and-portable-media-the-security-risk-in-your-desk-drawer/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/usb-drives-and-portable-media-the-security-risk-in-your-desk-drawer/</id>
        <published>2026-02-20T00:00:00.000Z</published>
        <updated>2026-02-20T00:00:00.000Z</updated>
        <summary>USB drives remain one of the easiest ways for data to leave your business and one of the quietest ways for threats to get in. Here&#39;s what Canadian SMBs need to know.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>Vendor and Third-Party Risk: How Your Suppliers Can Become Your Weakest Link</title>
        <link href="https://cybersecuritycanada.ca/news/posts/vendor-and-third-party-risk-how-your-suppliers-can-become-your-weakest-link/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/vendor-and-third-party-risk-how-your-suppliers-can-become-your-weakest-link/</id>
        <published>2026-02-14T00:00:00.000Z</published>
        <updated>2026-02-14T00:00:00.000Z</updated>
        <summary>Your cybersecurity is only as strong as the least secure vendor with access to your systems or data. Here&#39;s how Canadian small businesses can assess and manage third-party risk without a dedicated security team.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>Windows Notepad Vulnerability: What Canadian Businesses Should Know</title>
        <link href="https://cybersecuritycanada.ca/news/posts/windows-notepad-vulnerability-what-canadian-businesses-should-know/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/windows-notepad-vulnerability-what-canadian-businesses-should-know/</id>
        <published>2026-02-11T00:00:00.000Z</published>
        <updated>2026-02-11T00:00:00.000Z</updated>
        <summary>A critical flaw in Windows Notepad could let attackers take control of your PC through a simple file. Here&#39;s what Canadian business owners need to know and do.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Threats"/>
    </entry>
    <entry>
        <title>Notepad++ Supply Chain Attack: What Canadian Businesses Should Know</title>
        <link href="https://cybersecuritycanada.ca/news/posts/notepad-plus-plus-supply-chain-attack-what-canadian-businesses-should-know/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/notepad-plus-plus-supply-chain-attack-what-canadian-businesses-should-know/</id>
        <published>2026-02-10T00:00:00.000Z</published>
        <updated>2026-02-10T00:00:00.000Z</updated>
        <summary>A Chinese state-sponsored group hijacked Notepad++ updates for months, delivering targeted malware through a trusted update channel. Here&#39;s what happened and what to do.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Threats"/>
    </entry>
    <entry>
        <title>The Hidden Cost of Assuming Your Business Is Too Small to Attack</title>
        <link href="https://cybersecuritycanada.ca/news/posts/the-hidden-cost-of-assuming-your-business-is-too-small-to-attack/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/the-hidden-cost-of-assuming-your-business-is-too-small-to-attack/</id>
        <published>2026-02-10T00:00:00.000Z</published>
        <updated>2026-02-10T00:00:00.000Z</updated>
        <summary>The belief that your business is too small to be targeted isn&#39;t just wrong — it&#39;s the most expensive cybersecurity assumption a Canadian SMB can make. Here&#39;s what it actually costs.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>How to Use Your Cybersecurity Assessment Results</title>
        <link href="https://cybersecuritycanada.ca/news/posts/how-to-use-your-assessment-results/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/how-to-use-your-assessment-results/</id>
        <published>2026-02-07T00:00:00.000Z</published>
        <updated>2026-02-07T00:00:00.000Z</updated>
        <summary>Completed the assessment? Here&#39;s how to interpret your score, prioritize improvements, and build a practical security roadmap for your organization.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Guide"/>
    </entry>
    <entry>
        <title>Why Canadian SMBs Can No Longer Ignore Cybersecurity</title>
        <link href="https://cybersecuritycanada.ca/news/posts/why-canadian-smbs-need-cybersecurity/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/why-canadian-smbs-need-cybersecurity/</id>
        <published>2026-02-01T00:00:00.000Z</published>
        <updated>2026-02-01T00:00:00.000Z</updated>
        <summary>Canadian small businesses face growing cyber threats. Learn why cybersecurity has become a business necessity, not just an IT concern.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>When Cyber Attacks Become Physical Threats</title>
        <link href="https://cybersecuritycanada.ca/news/posts/when-cyber-attacks-become-physical-threats/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/when-cyber-attacks-become-physical-threats/</id>
        <published>2026-01-28T00:00:00.000Z</published>
        <updated>2026-01-28T00:00:00.000Z</updated>
        <summary>Cyber attacks don&#39;t always stay digital. Criminals are using email compromises, system hacks, and signal jamming as stepping stones to physical crimes like burglary and fraud.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Threats"/>
    </entry>
    <entry>
        <title>Backup and Recovery: 5 Assumptions That Fail When It Matters</title>
        <link href="https://cybersecuritycanada.ca/news/posts/backup-and-recovery-assumptions-that-fail/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/backup-and-recovery-assumptions-that-fail/</id>
        <published>2026-01-25T00:00:00.000Z</published>
        <updated>2026-01-25T00:00:00.000Z</updated>
        <summary>Most businesses think their backups are fine — until they try to restore from them. Here are five common backup assumptions that fail during a real incident.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>Why Your Canadian Business Needs an AI Usage Policy</title>
        <link href="https://cybersecuritycanada.ca/news/posts/why-your-business-needs-an-ai-usage-policy/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/why-your-business-needs-an-ai-usage-policy/</id>
        <published>2026-01-20T00:00:00.000Z</published>
        <updated>2026-01-20T00:00:00.000Z</updated>
        <summary>Your employees are already using AI tools — with or without your knowledge. Here&#39;s why a clear AI usage policy protects your business and what it should cover.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>Understanding Canada&#39;s Baseline Cyber Security Controls for SMBs</title>
        <link href="https://cybersecuritycanada.ca/news/posts/understanding-canadas-baseline-cyber-security-controls/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/understanding-canadas-baseline-cyber-security-controls/</id>
        <published>2026-01-15T00:00:00.000Z</published>
        <updated>2026-01-15T00:00:00.000Z</updated>
        <summary>The Canadian Centre for Cyber Security has published baseline controls specifically designed for small and medium organizations. Here&#39;s what you need to know.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Standards"/>
    </entry>
    <entry>
        <title>The Real Cost of Cyber Downtime for Canadian SMBs</title>
        <link href="https://cybersecuritycanada.ca/news/posts/the-real-cost-of-cyber-downtime-for-canadian-smbs/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/the-real-cost-of-cyber-downtime-for-canadian-smbs/</id>
        <published>2026-01-05T00:00:00.000Z</published>
        <updated>2026-01-05T00:00:00.000Z</updated>
        <summary>When systems go offline due to a cyber incident, the costs go far beyond the ransom demand. Here&#39;s what Canadian small businesses actually face.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Insights"/>
    </entry>
    <entry>
        <title>Business Email Compromise (BEC): Canada&#39;s Most Costly Cyber Threat</title>
        <link href="https://cybersecuritycanada.ca/news/posts/business-email-compromise-canadas-most-costly-cyber-threat/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/business-email-compromise-canadas-most-costly-cyber-threat/</id>
        <published>2025-12-30T00:00:00.000Z</published>
        <updated>2025-12-30T00:00:00.000Z</updated>
        <summary>Business email compromise doesn&#39;t use malware or exploit software vulnerabilities. It exploits trust — and it&#39;s responsible for more financial losses than any other form of cybercrime. Here&#39;s what Canadian businesses need to know.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Threats"/>
    </entry>
    <entry>
        <title>Remote Work Security for Canadian Businesses</title>
        <link href="https://cybersecuritycanada.ca/news/posts/remote-work-security-for-canadian-businesses/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/remote-work-security-for-canadian-businesses/</id>
        <published>2025-12-18T00:00:00.000Z</published>
        <updated>2025-12-18T00:00:00.000Z</updated>
        <summary>Remote and hybrid work is here to stay. Here&#39;s how Canadian SMBs can keep their data secure when employees work outside the office.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>Cloud Security Basics for Canadian Small Businesses</title>
        <link href="https://cybersecuritycanada.ca/news/posts/cloud-security-basics-for-canadian-small-businesses/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/cloud-security-basics-for-canadian-small-businesses/</id>
        <published>2025-12-12T00:00:00.000Z</published>
        <updated>2025-12-12T00:00:00.000Z</updated>
        <summary>Moving to the cloud doesn&#39;t mean your data is automatically secure. Microsoft 365, Google Workspace, and other cloud platforms require configuration — and the default settings often leave gaps. Here&#39;s what Canadian SMBs need to get right.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>How to Recognize Phishing Emails: A Guide for Canadian Businesses</title>
        <link href="https://cybersecuritycanada.ca/news/posts/how-to-recognize-phishing-emails/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/how-to-recognize-phishing-emails/</id>
        <published>2025-12-05T00:00:00.000Z</published>
        <updated>2025-12-05T00:00:00.000Z</updated>
        <summary>Phishing is the number one cyber threat to Canadian businesses. Learn the warning signs and how to protect your organization.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Threats"/>
    </entry>
    <entry>
        <title>Employee Security Awareness Training: What Actually Works</title>
        <link href="https://cybersecuritycanada.ca/news/posts/employee-security-awareness-training-what-actually-works/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/employee-security-awareness-training-what-actually-works/</id>
        <published>2025-11-28T00:00:00.000Z</published>
        <updated>2025-11-28T00:00:00.000Z</updated>
        <summary>Annual compliance videos don&#39;t change behaviour. Here&#39;s what the research says about effective security awareness training for Canadian small businesses — and how to build a program that actually reduces risk.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>Password Security: What Canadian Businesses Get Wrong</title>
        <link href="https://cybersecuritycanada.ca/news/posts/password-security-what-canadian-businesses-get-wrong/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/password-security-what-canadian-businesses-get-wrong/</id>
        <published>2025-11-20T00:00:00.000Z</published>
        <updated>2025-11-20T00:00:00.000Z</updated>
        <summary>Forced password rotation, short minimums, and no password manager — here are the most common password mistakes Canadian SMBs make and how to fix them.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>Multi-Factor Authentication: The Single Biggest Security Upgrade for Canadian SMBs</title>
        <link href="https://cybersecuritycanada.ca/news/posts/multi-factor-authentication-the-single-biggest-security-upgrade-for-canadian-smbs/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/multi-factor-authentication-the-single-biggest-security-upgrade-for-canadian-smbs/</id>
        <published>2025-11-10T00:00:00.000Z</published>
        <updated>2025-11-10T00:00:00.000Z</updated>
        <summary>MFA blocks over 99% of automated account attacks. It&#39;s free to enable on most business platforms, takes minutes to set up, and is increasingly required by cyber insurers. Here&#39;s what Canadian businesses need to know.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Best Practices"/>
    </entry>
    <entry>
        <title>Why Cybercriminals Target Small Businesses</title>
        <link href="https://cybersecuritycanada.ca/news/posts/why-cybercriminals-target-small-businesses/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/why-cybercriminals-target-small-businesses/</id>
        <published>2025-11-01T00:00:00.000Z</published>
        <updated>2025-11-01T00:00:00.000Z</updated>
        <summary>Small businesses are not too small to be targeted. Here&#39;s why cybercriminals see Canadian SMBs as attractive targets and what you can do about it.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Threats"/>
    </entry>
    <entry>
        <title>5 Easy Cybersecurity Wins for Canadian Small Businesses</title>
        <link href="https://cybersecuritycanada.ca/news/posts/5-easy-cybersecurity-wins-for-canadian-small-businesses/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/5-easy-cybersecurity-wins-for-canadian-small-businesses/</id>
        <published>2025-10-28T00:00:00.000Z</published>
        <updated>2025-10-28T00:00:00.000Z</updated>
        <summary>You don&#39;t need a massive budget or a dedicated IT team to meaningfully improve your cybersecurity. These five actions can be implemented quickly and address the most common ways Canadian small businesses get breached.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Guide"/>
    </entry>
    <entry>
        <title>Canada&#39;s Privacy Landscape: What Small Businesses Need to Know</title>
        <link href="https://cybersecuritycanada.ca/news/posts/canadas-privacy-landscape-what-small-businesses-need-to-know/" rel="alternate" type="text/html"/>
        <id>https://cybersecuritycanada.ca/news/posts/canadas-privacy-landscape-what-small-businesses-need-to-know/</id>
        <published>2025-10-15T00:00:00.000Z</published>
        <updated>2025-10-15T00:00:00.000Z</updated>
        <summary>PIPEDA, provincial laws, and breach reporting — a plain-language overview of the privacy obligations that apply to Canadian small businesses.</summary>
        <author>
            <name>Cybersecurity Canada</name>
        </author>
        <category term="Compliance"/>
    </entry>
</feed>
